Roadmap

Last updated: Mar 24, 2026


We are excited to share our priorities and upcoming features, designed to enhance security, simplify workflows, and empower you with greater efficiency and transparency.

AI-powered vulnerability scanner (in progress)

Completed: We built an AI-powered SAST scanner that automates vulnerability detection previously requiring manual analysis. It identifies SQL injections and XSS, with over 90% precision at automation speed.

Current focus: We are enhancing detection accuracy (precision and recall) and expanding CWE coverage to support a broader range of vulnerability types (aka weaknesses).

Fluid Attacks' peer reviewer assistant (in progress)

Overview: A complementary security approach that provides AI-powered comments on your pull requests to help prevent vulnerability injection before code is merged. This functionality will be exclusively available on the Advanced plan.

Current focus: Currently in development with upcoming availability for Azure DevOps and GitLab integrations for SAST and SCA techniques.

Scope management improvements (in progress)

Completed: Enhanced mobile application environment registration workflow for better usability.

Current focus: Implementing table filters for environments and files to improve navigation and management.

Roadmap: Group creation redesign to make it clear that groups require both repository and environment registration.

IntelliJ plugin enhancements (in progress)

Completed: Custom Fix and reattack features are now available.

Current focus: Building Autofix capability for enhanced remediation flexibility.

SCA fix recommendations (in progress)

Completed: CVE fix information is now available in our database and the platform, providing developers with immediate remediation guidance for vulnerable dependencies.

Current focus: Enhancing fix recommendations with three alternatives: (a) minimum version that fixes the CVE but may introduce new vulnerabilities, (b) minimum version that fixes without introducing new issues, and (c) nearest package version with no vulnerabilities. Rolling out these enhanced recommendations to VS Code, Cursor, and IntelliJ plugins.

On this page